Openbsd OpenSSH vulnerabilities

125 known vulnerabilities affecting openbsd/openssh.

Total CVEs
125
CISA KEV
0
Public exploits
22
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH43MEDIUM53LOW18

Vulnerabilities

Page 5 of 7
CVE-2006-4925MEDIUMCVSS 5.0v4.52006-09-29
CVE-2006-4925 [MEDIUM] CVE-2006-4925: packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending a packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL.
nvdosv
CVE-2006-4924HIGHCVSS 7.8PoCv1.2v1.2.1+54 more2006-09-27
CVE-2006-4924 [HIGH] CWE-399 CVE-2006-4924: sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.
nvdosv
CVE-2006-5051HIGHCVSS 8.1≤ 4.42006-09-27
CVE-2006-5051 [HIGH] CWE-415 CVE-2006-5051: Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of ser Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
nvdosv
CVE-2006-5052MEDIUMCVSS 5.0v1.2v1.2.1+54 more2006-09-27
CVE-2006-5052 [MEDIUM] CVE-2006-5052: Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows rem Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort."
nvdosv
CVE-2006-0883MEDIUMCVSS 5.0v3.8.1p12006-03-07
CVE-2006-0883 [MEDIUM] CWE-399 CVE-2006-0883: OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.
nvdosv
CVE-2006-0225MEDIUMCVSS 4.6v3.0v3.0.1+31 more2006-01-25
CVE-2006-0225 [MEDIUM] CVE-2006-0225: scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.
nvdosv
CVE-2005-2798MEDIUMCVSS 5.0v3.0v3.0.1+30 more2005-09-06
CVE-2005-2798 [MEDIUM] CVE-2005-2798: sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.
nvdosv
CVE-2005-2797MEDIUMCVSS 5.0v4.02005-09-06
CVE-2005-2797 [MEDIUM] CVE-2005-2797: OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" o OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, which may cause OpenSSH to enable the GatewayPorts functionality.
nvdosv
CVE-2005-2666LOWCVSS 1.2v3.0v3.0.1+28 more2005-08-23
CVE-2005-2666 [LOW] CWE-255 CVE-2005-2666: SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP a SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a list of additional targets that are more likely to have the same password or key.
nvdosv
CVE-2004-2760MEDIUMCVSS 6.8v3.5v3.5p12004-12-31
CVE-2004-2760 [MEDIUM] CVE-2004-2760: sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2
nvdosv
CVE-2004-2069MEDIUMCVSS 5.0v3.6.1p2v3.7.1p22004-12-31
CVE-2004-2069 [MEDIUM] CVE-2004-2069: sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).
nvdosv
CVE-2004-1653MEDIUMCVSS 6.4≤ 3.92004-08-31
CVE-2004-1653 [MEDIUM] CVE-2004-1653: The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authentic The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
nvd
CVE-2004-0175MEDIUMCVSS 4.3v3.0v3.0.1+13 more2004-08-18
CVE-2004-0175 [MEDIUM] CVE-2004-0175: Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.
nvdosv
CVE-2003-1562HIGHCVSS 7.6v1.2v1.2.1+43 more2003-12-31
CVE-2003-1562 [HIGH] CVE-2003-1562: sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interac sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vul
nvdosv
CVE-2003-0786CRITICALCVSS 10.0v3.7.1v3.7.1p12003-11-17
CVE-2003-0786 [CRITICAL] CVE-2003-0786: The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separati The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.
nvdosv
CVE-2003-0787HIGHCVSS 7.5v3.7.1v3.7.1p12003-11-17
CVE-2003-0787 [HIGH] CVE-2003-0787: The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an a The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.
nvdosv
CVE-2003-0695HIGHCVSS 7.5≤ 3.7.12003-10-06
CVE-2003-0695 [HIGH] CVE-2003-0695: Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.
nvdosv
CVE-2003-0682HIGHCVSS 7.5≤ 3.7.12003-10-06
CVE-2003-0682 [HIGH] CVE-2003-0682: "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
nvdosv
CVE-2003-0693CRITICALCVSS 10.0≤ 3.72003-09-22
CVE-2003-0693 [CRITICAL] CVE-2003-0693: A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remo A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.
nvdosv
CVE-2003-0386HIGHCVSS 7.5v3.6.12003-07-02
CVE-2003-0386 [HIGH] CVE-2003-0386: OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyRever OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a host from a system whose reverse DNS hostname contains the numeric IP address.
nvdosv